From Prompt to Pwn: Exploiting GPU Memory Errors During ML Inference
Jonas Roels, Adriaan Jacobs, Silviu Vlasceanu, Mahmoud Ammar, Stijn Volckaert
Abstract
GPUs accelerate a growing fraction of modern computing workloads. While prior work has studied the exploitation of memory errors in GPU applications written in C/C++ dialects, existing attacks rely on artificially introduced memory errors that grant attackers capabilities that may not arise when exploiting real-world GPU software. Consequently, GPU vendors and developers continue to largely treat such errors as reliability concerns rather than security issues, leaving vulnerabilities unpatched and potentially exploitable.
This paper challenges that assumption. We show, for the first time, that remote, unprivileged adversaries can trigger device-side memory errors in realistic ML applications under specific conditions. We develop controlled proof-of-concept exploits that escalate vulnerabilities in the PyTorch ML framework and the CuDF dataframe library into write-what-where primitives, and weaponize such errors to enable denial-of-service, targeted manipulation and degradation of ML models, sensitive data leakage, and device-side code injection.
To facilitate exploit construction, we design and implement a dynamic taint-tracking framework for NVIDIA GPUs that tracks attacker-controlled data flows to identify exploitable memory objects. Our findings demonstrate that adversaries can conduct memory-corruption attacks on vulnerable ML inference servers, highlighting the need to reassess prevailing assumptions about GPU memory safety and adopt essential mitigations, such as Write-XOR-eXecute, that are currently absent from modern GPUs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 938c3b7e-1930-424f-96b3-4483dfa925eaBuilds on15
- Efficient Memory Management for Large Language Model Serving with PagedAttentionWoosuk Kwon, Zhuohan Li, Siyuan Zhuang, Ying Sheng et al.SOSP 2023 · 1,016 citations
- Automatic Heap Layout Manipulation for ExploitationSean Heelan, Tom Melham, Daniel KroeningUSENIX Security 2018 · 62 citations
- Spy in the GPU-box: Covert and Side Channel Attacks on Multi-GPU SystemsSankha Baran Dutta, Hoda Naghibijouybari, Arjun Gupta, Nael B. Abu-Ghazaleh et al.ISCA 2023 · 41 citations
- Securing GPU via region-based bounds checkingJaewon Lee, Yonghae Kim, Jiashen Cao, Euna Kim et al.ISCA 2022 · 19 citations
- GPU.zip: On the Side-Channel Implications of Hardware-Based Graphical Data CompressionYingchen Wang, Riccardo Paccagnella, Zhao Gang, Willy R. Vasquez et al.S&P 2024 · 17 citations
Related papers
- GPUBreach: Privilege Escalation Attacks on GPUs Using RowhammerChris S. Lin, Yuqin Yan, Guozhen Ding, Joyce Qu et al.S&P 2026 · 8 citations
- GHost in the Shell: A GPU-to-Host Memory Attack and its MitigationSihyun Roh, Woohyuk Choi, Jaeyoung Chung, Yoochan Lee et al.S&P 2026 · 2 citations
- GPU Memory Exploitation for Fun and ProfitYanan Guo, Zhenkai Zhang, Jun YangUSENIX Security 2024 · 12 citations
- cuCatch: A Debugging Tool for Efficiently Catching Memory Safety Violations in CUDA ApplicationsMohamed Tarek Ibn Ziad, Sana Damani, Aamer Jaleel, Stephen W. Keckler et al.PLDI 2023 · 15 citations
- Demystifying and Exploiting ASLR on NVIDIA GPUsRuofan Zhu, Ganhao Chen, Wenbo Shen, Lyuye Zhang et al.S&P 2026 · 2 citations
